SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-62187

HIGH · CVSS 8.1 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The OpenClaw Feishu tools npm package allows unauthorized operations due to a flaw in its authorization checks, particularly affecting versions up to 2026.6.6. This vulnerability could be exploited by lower-trust callers or through misconfigured input paths, leading to potential unauthorized access or actions. Organizations using this package, especially those with sensitive configurations, should prioritize upgrading to version 2026.6.9 to mitigate the risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-62187
Severity
HIGH
CVSS
8.1
EPSS
0.21%

Original NVD Description

OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 could ignore per-account disablement. A lower-trust caller or a configured input path could perform actions that should have required a stronger authorization or policy check, resulting in unauthorized operations. The issue is fixed in version 2026.6.9. Impact depends on the operator's configuration and whether lower-trust input can reach the affected feature.

Related CVEs

Other vulnerabilities affecting the same vendor(s)